From 296046510bc213090ea9e69a7314abb79f4d792e Mon Sep 17 00:00:00 2001 From: Daniel Stenberg Date: Sun, 3 Aug 2003 21:33:25 +0000 Subject: [PATCH] serios info leakage! --- CHANGES | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/CHANGES b/CHANGES index 138d7c4bb..94a5318a1 100644 --- a/CHANGES +++ b/CHANGES @@ -6,6 +6,14 @@ Changelog +Daniel (3 August) +- When proxy authentication is used in a CONNECT request (as used for all SSL + connects and otherwise enforced tunnel-thru-proxy requests), the same + authentication header is also wrongly sent to the remote host. + + This is a rather significant info leak. I've fixed it now and mailed a patch + and warning to the mailing lists. + Daniel (1 August) - David Byron provided a patch to make 7.10.6 build correctly with the compressed hugehelp.c source file.